Explore skills

4,475 skills found

Category alert

Get new Segurança skills every Monday

security-audit

3.1k

Deep security audit covering OWASP Top 10, authentication, authorization, data protection, dependency vulnerabilities, and secrets scanning. Delegates to the Centinela (QA) agent.

Segurançaby davepoon

aurakit

3.1k

Sonnet Amplified fullstack engine. 34 modes, SEC-01~15 OWASP security, 13 runtime hooks, 75% token reduction. Install: npx @smorky85/aurakit

Segurançaby davepoon

remediation

3.1k

Get a context-aware remediation plan for a vulnerability with fix verification steps

Segurançaby davepoon

gsd:audit-uat

3.1k

Cross-phase audit of all outstanding UAT and verification items

Segurançaby davepoon

vuln

3.1k

Look up a vulnerability by ID or list all vulnerabilities for a package

Segurançaby davepoon

exploits

3.1k

Analyze exploit intelligence for a vulnerability against the current repository

Segurança#aiby davepoon

fix

3.1k

Get fix intelligence for a vulnerability and propose concrete remediation for the current repository

Segurançaby davepoon

bb-local-toolkit

2.6k

This skill details a complete bug bounty workflow, encompassing reconnaissance, pre-hunt learning, and vulnerability hunting for a wide range of common web exploits like IDOR, XSS, and SQLi.

Segurança#sql#aiby elementalsouls

bug-bounty

2.6k

A complete bug bounty workflow encompassing reconnaissance (subdomain enumeration, asset discovery, fingerprinting), pre-hunt learning (disclosed reports, tech stack research), and vulnerability hunting for various issues including IDOR, SSRF, XSS, SQLi, and advanced techniques like GraphQL and HTTP smuggling.

Segurança#sql#aiby elementalsouls

m365-entra-attack

2.6k

This skill details a Microsoft 365 / Entra ID red-team attack chain, reflecting current 2026 realities, covering AADSTS codes, user enumeration, Smart Lockout math, Conditional Access bypass, ROPC + SAML SSO flows, and Burp/Playwright templates. It's derived from authorized red-team operations that uncovered pre-existing lockouts and CA-blocked credentials, combined with real-time external attacker observations.

Segurança#aiby elementalsouls

hunt-api-misconfig

2.6k

Identifies and exploits API security misconfigurations such as mass assignment, JWT attacks, prototype pollution, CORS, and HTTP verb tampering.

Segurança#apiby elementalsouls

hunt-race-condition

2.6k

A skill for hunting race condition vulnerabilities, developed from 12 public bug bounty reports. It covers modern HTTP/2 single-packet attack cases and common scenarios like coupon double-redemption, gift-card double-spend, MFA-OTP-validate race, account-create race, and crypto token double-spend.

Segurançaby elementalsouls